CVE-2026-32297 is a high-severity vulnerability (CVSS 7.5) affecting the Angeet ES3 KVM, allowing remote, unauthenticated attackers to write arbitrary files, including configuration files or system binaries. This flaw, categorized as CWE-306, has low attack complexity and could lead to complete system takeover due to high integrity impact. While there is no public exploit code or evidence of active exploitation, the vulnerability is on the "Hot List" and has garnered significant community attention, with urgent calls for immediate isolation and access restriction due to the lack of a patch.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:angeet:es3_kvm_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.